IT security intelligence. Since 2006.Cloudflare services
TRUST-IT / Practical guide

Brand impersonation: respond to fake domains, profiles and emails

A fraudulent website, executive profile or payment message needs a coordinated response. Learn what to preserve, how to separate impersonation from account compromise, and what a useful escalation package contains.

Illustrative scene of specialists examining potential online impersonation
About 6 min read

Establish which identity is being misused

Brand impersonation is the use of a trusted organisation’s or person’s identity to mislead someone. The visible symptom may be a lookalike domain, a cloned website, a social profile, an advertisement or a message. Start with the exact address or account identifier, the claimed identity, the requested action and the people exposed. A similar name alone does not establish fraud; document the actual misleading behaviour.

Separate three possibilities: misuse of your real domain in a forged message, an attacker-controlled domain that resembles yours, and compromise of a genuine account. They require different technical checks and response owners. A fraudulent instruction sent through a real, compromised mailbox can pass email authentication. A lookalike domain may have correctly configured authentication for its own name.

Preserve a small, useful evidence package

Keep original suspicious messages with their full headers and attachments through an agreed evidence-handling process. Record the full URL or profile identifier, observation time and time zone, screenshots with context, relevant message identifiers and the action requested. Retain originals separately from annotated working copies. Record who collected each item, how, and any limitations; avoid circulating confidential customer information to everyone involved.

Specialists can examine relevant public domain records, DNS responses, certificate information and observable page behaviour within an authorised scope. Shared hosting, a certificate or a registration timestamp is a lead, not proof of common ownership or the human operator. Do not enter credentials into the suspicious site, download unknown files or engage the impersonator to “test” the fraud.

A response path with clear decision points

  1. Identify

    Record the claimed identity, exact location and requested action.

  2. Preserve

    Keep original messages, observations and collection context.

  3. Protect

    Verify payment requests and restrict confirmed exposure with the responsible team.

  4. Escalate

    Send relevant evidence to the correct provider; track decisions and recurrence.

Reduce exposure while the investigation continues

Use a verified communication channel to tell the relevant finance, customer support, IT or executive office team what is known. Preserve exact indicators before sharing them as warnings, and make clear which are confirmed and which remain under review. Internal filtering or blocking decisions should consider legitimate business dependencies and be recorded with an owner and review time.

If payment is involved, the authorised finance contact should speak promptly to the bank through a verified channel. Independently verify changes in payment details using a previously established contact route, not a number supplied in the suspicious message. The FBI recommends this kind of independent verification for business email compromise. A technical investigation and a bank recovery request are separate actions; neither establishes that funds can be recovered.

Send the right evidence to the right recipient

Identify the service responsible for the observed abuse: a social platform for a fake profile, a hosting provider for a malicious page, or a registrar for domain-related abuse. A useful report explains what is being impersonated, the exact location, the observed harmful behaviour, the evidence and a contact authorised to represent the affected organisation. Retain submission receipts and case identifiers so later reviewers can reconstruct the response.

ICANN describes a registrar-first reporting route for relevant generic top-level domain abuse, with contractual-compliance escalation in appropriate cases. Country-code domains and content or trademark disputes can follow different processes. A provider assesses the report under its own remit and policies; investigation does not guarantee removal or a fixed takedown time. Legal advisers should guide rights-based claims and any procedural requirements.

Understand what email authentication can and cannot fix

SPF identifies authorised sending infrastructure, DKIM provides a domain-linked message signature, and DMARC evaluates alignment with the domain shown in the From address and publishes handling and reporting policy. Review legitimate senders, forwarding and third-party mailing services before changing enforcement, then monitor delivery and authentication results. A policy change without an inventory of business senders can disrupt legitimate mail.

These controls help protect your domain from unauthorised use. They do not reserve similar-looking domain names, remove social profiles, prove a sender’s business intent or make a compromised genuine mailbox safe. Combine them with account protection, reliable recovery channels, payment verification and an escalation process for external impersonation.

Distinguish the signal from the conclusion

This is an illustrative triage matrix, not a finding about a real organisation.

On a small screen, scroll the table sideways to compare all columns.

Distinguish the signal from the conclusion
Observed signalWhat to establish nextWhat it does not prove
Similar domain or shared infrastructureExact spelling, recorded behaviour, relevant public records and affected workflow.Common ownership, criminal intent or the identity of a person.
Payment instruction from a known addressOriginal message, independent authorisation and relevant account activity.That the request is genuine simply because the email authenticated.
Profile using a name and photographStable account identifier, claimed affiliation and misleading conduct.That every account with the same name is fraudulent.

Agree an investigation and monitoring scope

For an enterprise, identify brand variants, subsidiaries, executive identities, priority countries, languages and the business processes at risk. For a family office or private client, include authorised representatives and sensitive payment relationships only where relevant and agreed. Define coverage sources, review frequency, alert recipients and escalation thresholds. Monitoring cannot promise visibility into every private group, platform or newly created domain.

Ask for a report that distinguishes confirmed abuse, suspicious leads, false positives and unresolved findings. Each actionable item should include an evidence reference, business relevance, recommended action, responsible owner and next review. Useful measures include time to assess a report, completeness of evidence, verified actions and recurrence; raw alert volume alone says little about protection.

Prepare a useful enquiry for TRUST-IT

Tell us whether the concern involves a domain, profile, email or payment request; when it was first observed; whether activity appears ongoing; and who can authorise the investigation. A short description is enough for the initial public form or AI assistant. Credentials, identity documents, financial records and confidential evidence should be exchanged only through a channel agreed with the team.

TRUST-IT can scope public-source research, digital brand intelligence and related email, cloud or device investigation where authorised. We agree the questions, evidence access, deliverables, reporting recipients and response responsibilities before work begins. If the genuine account may be compromised, use the Microsoft 365 response guide alongside the brand investigation rather than treating every symptom as an external fake.

Further reading

Put the guidance to work

Open-source research, threat intelligence, social media monitoring, and assessment of impersonation and digital exposure.

Threat intelligence & brand protection

What’s your next
technology challenge?

TRUST-IT / FIND YOUR NEXT STEP

How can we help?

Popular topics

Search the public TRUST-IT website.

    TRUST-IT · AI assistant
    TRUST-IT

    How can we help?

    Explore our services, ask a question or tell us what you need. You will be speaking with our AI assistant.

    When you continue, Ultimo-Bots loads the chat. Your name, email and conversation are recorded so TRUST-IT can respond, and our team receives enquiry notifications. Phone, company and role are optional.

    Please do not share passwords, evidence files or sensitive information.

    Read our privacy notice

    Prefer to speak with our team? Contact TRUST-IT